Data Localisation in India: RBI Payment Data, DPDP Rules

Get in touch with us

    Your information is confidential and secure


    Get in touch with us

      Your information is confidential and secure


      Data localisation requirements in India are not a single law. They are a stack of sectoral directions layered on top of a general data protection statute, and each layer picks up a different slice of a company’s data. A fintech processing UPI payments, a SaaS platform serving Indian enterprise clients, and a broker-dealer running analytics in the cloud are each subject to a different combination of rules, and a company that is all three at once (which is common for embedded finance and neo-banking products) has to satisfy every layer simultaneously. This article maps the Reserve Bank of India’s payment data direction, the Securities and Exchange Board of India’s cloud framework, and the Digital Personal Data Protection Act, 2023 and its Rules of 2025, against the kind of dual-region architecture that most venture-funded Indian companies actually run.

      Does India legally require companies to store data locally?

      There is no blanket data localisation law in India. The DPDP Act, 2023 permits cross-border transfer of personal data by default and restricts it only where the Central Government issues a specific order under Section 16. Sectoral regulators take a stricter approach: the RBI’s 2018 payment data direction and SEBI’s 2023 cloud framework both require India-only storage for the data within their respective jurisdictions, regardless of what the DPDP Act permits.

      What does data localisation mean under Indian law?

      Data localisation, in the Indian regulatory context, means a legal requirement to store data on servers physically located within India, sometimes alongside a parallel restriction on processing that data outside the country. India has never enacted a single omnibus localisation statute. Instead, three separate regimes apply cumulatively depending on the sector and the type of data involved.

      • Sectoral localisation: a specific regulator (RBI, SEBI, IRDAI) mandates in-country storage for the data it regulates, irrespective of the general data protection law
      • General cross-border restriction: the DPDP Act, 2023 permits transfer abroad by default, subject to government-notified restrictions on specific destinations under Section 16
      • Significant Data Fiduciary overlay: entities designated as Significant Data Fiduciaries (SDFs) under Section 10 of the DPDP Act face additional government-specified restrictions on transferring certain categories of data, once such designation and restrictions are notified

      This layered structure means a founder cannot answer “do I need to localise my data” with a single yes or no. The correct question is which regulator’s data this is, and each answer points to a different rule.

      How does the RBI’s payment data localisation direction apply to fintech companies?

      The RBI’s direction, issued as circular DPSS.CO.OD No.2785/06.08.005/2017-18 dated April 6, 2018 on “Storage of Payment System Data”, requires all Payment System Operators (PSOs), the banks that support them, and every service provider engaged by a PSO in the payments chain, to store the entire data relating to payment systems they operate only in a system located in India (Payment and Settlement Systems Act, 2007, Section 17 enforcement powers). This applies whether the PSO is Indian-incorporated or a foreign card network operating in India.

      The RBI’s FAQ of June 26, 2019 clarified the scope of the direction and remains the operative interpretation, since the direction itself has not been superseded by the DPDP framework. The data that must be stored only in India includes:

      Data categoryWhat it coversApplies to
      End-to-end transaction detailsThe full payment message and instruction data, from initiation to settlementAll PSOs and their service providers
      Customer identifying dataName, mobile number, email, Aadhaar number, PAN, where collected as part of the transactionPSOs, banks, payment gateways
      Payment sensitive dataCard details, UPI handles, wallet balances, and other instrument-specific dataCard networks, wallet issuers, UPI apps
      Payment credentialsPINs, passwords and other authentication factors used to authorise a transactionAll system providers holding such credentials

      Two nuances matter for a company with offshore engineering:

      First, the RBI’s FAQ confirms there is no bar on processing payment transactions outside India, but it attaches a hard clock to it: where processing happens abroad, the data must be deleted from the foreign systems and brought back to India within one business day or 24 hours from payment processing, whichever is earlier. Any subsequent activity, such as settlement processing done outside India, has to happen on a near real-time basis, with the data still coming to rest only in India. A fintech running its transaction-processing microservice on a server in Singapore has a same-day window to purge that server and land the authoritative record in an Indian database, not an open-ended one. One narrow carve-out exists: foreign banks that RBI had specifically permitted to store banking data abroad before the 2018 direction may continue to do so for domestic transactions only if the data is also stored in India, and for cross-border transactions a copy of the domestic component must additionally be stored abroad.

      Second, compliance is not self-certified. PSOs are required to report compliance to the RBI and submit a Board-approved System Audit Report (SAR) prepared by a CERT-In empanelled auditor within the RBI’s prescribed timeline. The RBI has used this audit trail as the basis for enforcement: it has barred more than one global card network from onboarding new domestic customers for non-compliance with this direction, with the restriction lifted only once the SAR confirmed remediation.

      Does RBI’s localisation rule extend beyond payments into lending data?

      Yes, and this is the update that most content on this topic has not caught up with. The RBI’s 2018 direction covers payment system data specifically. Digital lending is governed separately, and that regime changed materially in 2025.

      The RBI first extended data localisation into digital lending through its September 2022 Guidelines on Digital Lending, which required Regulated Entities (REs, meaning banks and NBFCs) and their Lending Service Providers (LSPs) to store all data, both payment and non-payment, on servers located in India, and required biometric data to be held by the RE itself rather than by a lending partner. That circular has since been repealed. The Reserve Bank of India (Digital Lending) Directions, 2025 (RBI/2025-26/36, DOR.STR.REC.19/21.07.001/2025-26 dated May 8, 2025) replaced both the 2022 Guidelines and the 2023 Default Loss Guarantee Guidelines with a stricter regime that a fintech running an offshore-first stack needs to read carefully:

      • All personal data collected in a digital lending relationship must be stored on servers located within India
      • If any part of that data is processed on a server outside India, it must be deleted from the foreign server and repatriated to India within 24 hours of processing
      • Storage of biometric data is prohibited outright unless another law explicitly permits it
      • REs must certify, on the RBI’s Centralised Information Management System (CIMS) portal, that every Digital Lending App (DLA) they operate or work with complies with this data localisation requirement

      The 24-hour repatriation clock is the detail that catches most engineering teams off guard. A lending fintech running fraud scoring or underwriting models on an offshore compute cluster cannot treat that cluster as a place data quietly sits between batch jobs; the data has to be purged from the foreign server and confirmed back in an India-region store within a single day of processing, and the RE bears the compliance obligation even where an LSP or a third-party model vendor is doing the actual processing.

      What does the DPDP Act, 2023 and DPDP Rules, 2025 say about cross-border data transfer?

      The Digital Personal Data Protection Act, 2023, along with the Digital Personal Data Protection Rules, 2025 notified by the Ministry of Electronics and Information Technology (MeitY) on November 13, 2025, takes a materially different approach from the RBI. Section 16 of the DPDP Act permits transfer of personal data outside India by default, and Rule 15 of the DPDP Rules operationalises this as a “blacklist” model: transfers are allowed to any country or entity except where the Central Government has issued a general or special order restricting transfer to that destination.

      As of the date of this article, the Central Government has not notified any restricted country list under Rule 15, which means cross-border transfers of personal data governed purely by the DPDP Act face no destination-based restriction in practice, even though the legal mechanism to impose one exists and can be activated without advance notice or a stated justification.

      This is a deliberate softening from earlier drafts. The Justice Srikrishna Committee’s 2018 report recommended mandatory in-country processing for a “critical” category of data, and the 2019 Personal Data Protection Bill carried that forward with a sensitive-versus-critical classification that required local mirroring at minimum. After the Bill went through a Joint Parliamentary Committee in 2021 and was withdrawn in August 2022 over industry pushback on compliance cost, the redrafted DPDP Act of 2023 dropped blanket localisation in favour of the permissive, government-triggered restriction model that Rule 15 now implements. A company evaluating its exposure under the general DPDP regime is dealing with a materially lighter touch than what was on the table as recently as 2021, even though the sectoral rules below never softened.

      The DPDP Rules, 2025 come into force in three phases from the November 13, 2025 notification date:

      • Immediately: the Data Protection Board of India‘s foundational and procedural provisions
      • One year after notification (from November 13, 2026): Consent Manager registration and related provisions
      • Eighteen months after notification (from May 13, 2027): the substantive obligations on Data Fiduciaries under Sections 8 to 15, the Section 16 cross-border regime, and the Section 33 penalty schedule

      This staggered commencement is the detail most competitor content misses. A company is not yet exposed to DPDP penalties for cross-border transfer today, but the eighteen-month runway is meant to be used to re-architect data flows before the obligations bite, not to defer the decision until May 2027.

      Two categories of entity face a stricter version of this rule:

      • Significant Data Fiduciaries (SDFs), designated by the Central Government under Section 10 based on volume and sensitivity of data processed, risk to Data Principals, and considerations of sovereignty and public order, face additional government-specified restrictions on transferring certain categories of personal and traffic data outside India. No SDFs have been designated as of this writing, but large-scale fintech and consumer SaaS platforms are the most likely candidates once designation begins
      • Entities also regulated by a sectoral law (RBI, SEBI, IRDAI) remain bound by that sectoral localisation rule regardless of what the DPDP Act permits. The DPDP Rules, 2025 expressly preserve sectoral localisation obligations rather than displacing them

      A live development worth tracking: at a stakeholder consultation on January 22 to 23, 2026, MeitY proposed cutting the SDF compliance window from eighteen months to twelve, and bringing the cross-border transfer restriction and the government’s power to call for information into force immediately rather than waiting for May 2027. As of this writing, that proposal remains a consultation record, not a gazetted amendment, and the May 13, 2027 commencement date stated above is still the operative one. A company timing its SDF or cross-border readiness work should build to that date but keep an eye on MeitY’s notifications, since this is the one part of the DPDP timeline the government has openly signalled it wants to move earlier.

      Does SEBI’s cloud framework add a separate localisation layer?

      Yes, and it is frequently missed by fintech and SaaS teams that assume DPDP and RBI cover the field. SEBI’s Framework for Adoption of Cloud Services by SEBI Regulated Entities, issued via circular SEBI/HO/ITD/ITD_VAPT/P/CIR/2023/033 dated March 6, 2023, applies to stockbrokers, depository participants, mutual fund houses, KYC Registration Agencies, investment advisers, and any other entity registered with SEBI. This is directly relevant to wealth-tech and broking-adjacent fintech products, which frequently sit on the same cloud infrastructure as their core payments stack.

      Principle 3 of the framework, titled “Data Ownership and Data Localization”, requires that storage and processing of a Regulated Entity’s data, including logs and any other information in any form, reside and be processed only within the legal boundaries of India. For investors incorporated outside India, the Regulated Entity must still keep the original data, transactions, and logs accessible and usable within India. SEBI gave Regulated Entities twelve months from the circular date to bring existing cloud arrangements into compliance, with immediate effect for any new cloud onboarding.

      The practical overlap with RBI’s direction is not automatic. A payment aggregator that is not itself SEBI-registered is not bound by Principle 3. But a fintech that has added a broking, mutual fund distribution, or investment advisory licence to its stack, a common growth-stage move, brings its entire cloud environment under a second, independently enforced localisation obligation, including for logs, which the RBI direction does not explicitly name.

      What other sectoral rules require data localisation beyond RBI and SEBI?

      A handful of narrower sectoral rules regularly catch fintech and SaaS teams that have only mapped the three headline regimes. None of these carries the enforcement profile of the RBI direction, but each is a real, independently enforceable obligation, and the Aadhaar rule below is the most recent and most operationally demanding of the group.

      RuleRegulatorWhat it requiresWho it hits
      Aadhaar Data Vault mandateUIDAI, Circular No. 14 of 2025 dated November 4, 2025Any Aadhaar number and connected eKYC data must sit in a dedicated Aadhaar Data Vault, hosted either on the entity’s own premises in India or on a MeitY-empanelled Government Community CloudAny fintech, bank, or SaaS platform doing Aadhaar-based eKYC or authentication as an AUA or KUA
      Insurance records localisationIRDAI (Maintenance of Insurance Records) Regulations, 2015, Regulation 3(9)All records relating to insurance policies issued and claims made in India, including electronic records, must be stored within IndiaInsurers and insurtech platforms handling policy or claims data
      Telecom subscriber dataDepartment of Telecommunications, Unified License conditionsSubscriber account and call detail information for Indian telecom users must be stored on servers located in IndiaTelecom operators and SaaS platforms that ingest telecom subscriber data (SMS gateways, OTP aggregators)
      Books of account backupCompanies Act, 2013, Section 128Every company must maintain its books of account, and a back-up of the same, at its registered office in India, even where the primary accounting system is hosted on a foreign serverEvery Indian-incorporated company, regardless of sector

      The Aadhaar rule deserves particular attention for any fintech doing digital onboarding. UIDAI’s Circular No. 14 of 2025 supersedes its earlier 2017 guidance and requires every Requesting Entity to store Aadhaar numbers and connected eKYC data (the XML response containing the Aadhaar number and demographic details) in a segregated Aadhaar Data Vault, not in the general application database, even an encrypted one. The vault has to be hosted either on the entity’s own secure premises within India or on a cloud platform from MeitY’s empanelled list of Government Community Cloud providers. Storing a tokenised or encrypted version of the Aadhaar number in an ordinary offshore database, a common shortcut, does not satisfy this rule; the vault itself has to sit in an approved Indian environment.

      How do these layers stack for a company running offshore infrastructure?

      The honest answer is that most offshore-first architectures were never designed with any of this in mind, and the fix is rarely a full repatriation. It is usually a targeted re-architecture of where specific data classes come to rest.

      Data classGoverning ruleTypical offshore setupWhat usually has to change
      Payment transaction records, UPI/card dataRBI PSS circular, 2018Primary transaction DB in AWS Singapore or GCP USOffshore-processed data must be deleted and repatriated within 24 hours (or one business day, whichever is earlier); the India-region copy must be the authoritative store, not a mirror
      Digital lending data (loan applications, offers, disbursal records)RBI (Digital Lending) Directions, 2025Underwriting or fraud-scoring pipeline on an offshore compute clusterOffshore-processed data must be deleted from the foreign server and repatriated to India within 24 hours; biometric data cannot be stored at all
      Aadhaar numbers and eKYC responsesUIDAI Circular No. 14 of 2025Tokenised or encrypted Aadhaar data inside the general offshore application databaseAadhaar data must move into a dedicated Aadhaar Data Vault hosted on-premises in India or on a MeitY-empanelled Government Community Cloud
      General personal data (KYC, user profiles) not tied to paymentsDPDP Act, Section 16Multi-region replica, US or EU primaryNo forced localisation today; document the legal basis and monitor for a Section 16 restriction notification
      SEBI RE data (broking, MF distribution, logs)SEBI cloud framework, Principle 3Shared cloud environment with the fintech’s core stackLogs and RE-specific data need a dedicated India-only storage path, separate from the general application database
      Cybersecurity and system logsCERT-In Cybersecurity Directions, 2022Centralised offshore SIEM/logging platformLogs may stay on the offshore SIEM, but a copy must be retained within Indian jurisdiction and produced to CERT-In on request within the 180-day retention window
      Backups and disaster recovery copiesFollows the primary data’s governing ruleDR region often chosen for cost, frequently outside IndiaDR copies of RBI-governed, UIDAI-governed, or SEBI RE data must also sit in India; an offshore-only DR region defeats the localisation requirement even if production is compliant

      A few architectural patterns come up repeatedly in Treelife’s advisory work with fintech and SaaS clients:

      • Region-pinning the payments database separately from the rest of the application stack, so only the RBI-governed data moves, not the entire product
      • Splitting logging pipelines so RBI- and SEBI-governed transaction logs are exported to an India-region log store, while general application telemetry continues on the existing offshore SIEM
      • Treating disaster recovery as a compliance surface, not just an engineering one: an India-only production database with a Singapore-only DR replica is a common but unremediated gap
      • Auditing vendor contracts with cloud service providers and payment gateways to confirm the vendor itself is contractually bound to store the relevant data only in India, since RBI’s direction extends liability to every service provider in the PSO’s chain

      Not sure which data has to move to India? Let’s Talk

      What data can be processed abroad if the final copy is stored in India?

      This is the single most consequential nuance in the RBI regime, and the one that lets an offshore engineering team keep most of its stack intact. The RBI’s FAQ confirms that a PSO may process payment transactions outside India, run fraud detection, reconciliation, or analytics on servers anywhere in the world, provided the data is deleted from the foreign system and brought back to India within one business day or 24 hours of processing, whichever is earlier, so that it comes to rest only in an Indian-located system. Real-time replication to an offshore primary with an India-region “mirror” does not satisfy this; the India-based copy has to be the authoritative store, not a secondary one, and the 24-hour clock runs regardless.

      Common mistakes that cost founders time and money

      • Treating DPDP compliance as sufficient for a payments business. DPDP’s permissive cross-border stance does not override RBI’s storage-only-in-India direction. A fintech that has done a DPDP gap assessment and concluded it is compliant may still be in breach of the 2018 PSS circular, which carries independent RBI supervisory action, including onboarding bans of the kind RBI has already imposed on more than one global card network
      • Assuming mirroring satisfies the RBI direction. Storing a secondary copy in India while the primary transactional database remains offshore does not meet the “stored only in India” standard; RBI’s audit process (the System Audit Report) is designed to catch exactly this pattern
      • Missing the SEBI overlay after adding a financial licence. Companies that expand from payments into wealth management or MF distribution frequently forget that their existing cloud environment now needs a Principle 3 compliant data and log storage path, on top of whatever RBI already required
      • Leaving disaster recovery out of the localisation review. Compliance reviews often audit the production database and stop there, missing that backup and DR replicas of RBI- or SEBI-governed data sitting outside India are an independent, auditable gap
      • Relying on the repealed 2022 Digital Lending Guidelines. Lending fintechs that mapped their compliance against the September 2022 circular need to re-check against the Reserve Bank of India (Digital Lending) Directions, 2025, which replaced it with the stricter 24-hour offshore repatriation rule and an outright ban on biometric data storage
      • Storing tokenised Aadhaar data outside the mandated vault. Encrypting or tokenising an Aadhaar number before storing it in a general offshore database does not satisfy UIDAI’s Circular No. 14 of 2025; the Aadhaar Data Vault itself has to be hosted on-premises in India or on an approved Government Community Cloud
      • Waiting for the DPDP Rules’ May 2027 commencement date to start re-architecting. The eighteen-month phase-in exists so that companies build the documentation and data-flow infrastructure in advance; a Significant Data Fiduciary designation, once it arrives, does not come with an implementation grace period for restrictions the government has already notified

      FAQ’s on Data Localisation in India

      Q: Does the DPDP Act, 2023 require data localisation for all Indian companies?
      A: No. The DPDP Act permits cross-border transfer of personal data by default under Section 16, restricting it only to destinations the Central Government specifically notifies. No such restricted list has been notified as of this writing. Sectoral rules from RBI, SEBI, and IRDAI impose separate, independent localisation obligations that apply regardless of the DPDP Act’s general position.

      Q: What is the cost of becoming compliant with RBI’s payment data localisation direction?
      A: Cost depends on whether the company needs to migrate an existing offshore-primary database to India or simply add an India-region write path alongside existing infrastructure. Budget for the System Audit Report (SAR) fee charged by a CERT-In empanelled auditor, cloud migration or re-architecture costs, and legal review of vendor contracts to confirm sub-processor compliance.

      Q: How long does a data localisation compliance project typically take?
      A: A gap assessment and data flow mapping exercise typically takes two to four weeks. Remediation, particularly database region migration and DR replica realignment, commonly takes six to twelve weeks depending on data volume and downtime tolerance, followed by the SAR audit cycle.

      Q: What documentation does RBI expect for payment data storage compliance?
      A: A Board-approved System Audit Report from a CERT-In empanelled auditor, a data flow diagram covering primary storage, backups, and sub-processors, and written confirmation from every service provider in the payment chain that they store the relevant data only in India.

      Q: Do foreign card networks and payment gateways operating in India need to comply with RBI’s localisation direction?
      A: Yes. The RBI’s direction applies to all Payment System Operators authorised under the Payment and Settlement Systems Act, 2007, and this has been enforced against foreign entities, including more than one global card network, which have faced onboarding restrictions for non-compliance.

      Q: Is data localisation required for a SaaS company that has no payments or capital markets exposure?
      A: Generally no, beyond the general DPDP Act obligations, which do not currently mandate localisation. A pure B2B SaaS platform with no RBI or SEBI licensing is governed primarily by the DPDP Act’s consent, security, and breach notification requirements, not a storage-location mandate, unless it later adds a regulated financial product.

      Q: What is a Significant Data Fiduciary and does it change localisation obligations?
      A: A Significant Data Fiduciary (SDF) is an entity the Central Government designates under Section 10 of the DPDP Act based on the volume and sensitivity of data it processes and its potential impact on sovereignty, electoral integrity, or public order. SDFs face additional obligations, including possible government-specified restrictions on transferring certain data categories abroad, once designation and the specific restrictions are notified. No SDFs have been designated yet.

      Q: How does CERT-In’s 6-hour incident reporting rule interact with data localisation?
      A: The CERT-In Cybersecurity Directions, 2022 require reporting of specified cybersecurity incidents within six hours of detection and require ICT system logs to be maintained for a rolling 180-day period. CERT-In’s own FAQs clarify that logs may be stored outside India provided a copy is retained within Indian jurisdiction and produced to CERT-In on request. This is a related but distinct obligation from RBI’s payment data storage direction and applies more broadly across sectors.

      Q: Do digital lending apps still follow the RBI’s 2022 data localisation guidelines?
      A: No. The Reserve Bank of India (Digital Lending) Directions, 2025 (RBI/2025-26/36 dated May 8, 2025) repealed the September 2022 Guidelines on Digital Lending. The current rule requires all borrower data to be stored on servers in India, requires any data processed offshore to be deleted and repatriated to India within 24 hours, and prohibits storage of biometric data outright unless another law explicitly permits it.

      Q: Does Aadhaar-based eKYC data have to be stored separately from the rest of a fintech’s database?
      A: Yes. UIDAI’s Circular No. 14 of 2025 requires every Requesting Entity to store Aadhaar numbers and connected eKYC data in a dedicated Aadhaar Data Vault, hosted either on the entity’s own premises in India or on a MeitY-empanelled Government Community Cloud, separate from the entity’s general application database.

      Q: What happens if a fintech is found non-compliant with RBI’s data localisation direction during a bank partnership audit?
      A: A bank partner will typically require remediation before proceeding, and in cases the RBI itself identifies through supervisory review, it has imposed onboarding restrictions, barring the non-compliant entity from adding new domestic customers until a Board-approved System Audit Report confirms compliance, as it has done with more than one global card network in the past.

      Q: Do venture capital investors ask about data localisation during due diligence?
      A: Increasingly yes, particularly for fintech and any SaaS company with enterprise clients in regulated sectors. Investors and their legal counsel typically request the data flow architecture, any RBI or SEBI compliance filings, and confirmation of the physical location of production databases and backups as part of legal due diligence.

      Q: Does data localisation apply to a group structure where the Indian operating entity uses a foreign parent’s shared cloud infrastructure?
      A: Yes. RBI’s direction extends to every service provider engaged by a Payment System Operator, including a foreign parent providing shared infrastructure, and the responsibility for compliance remains with the Indian PSO regardless of who owns or operates the underlying servers.

      Q: What is the difference between data mirroring and data localisation under RBI’s rules?
      A: Data mirroring, storing a secondary copy in India while the primary authoritative copy remains offshore, does not satisfy RBI’s requirement. The direction requires that the entire relevant data be stored in a system located only in India, meaning the India-based copy must be the authoritative store, not a backup of an offshore primary. Where processing genuinely happens abroad, RBI’s FAQ gives a one business day or 24-hour window, whichever is earlier, to delete the data from the foreign system and land it back in India.

      Q: Will the DPDP Rules, 2025 eventually override RBI and SEBI’s localisation requirements?
      A: No. The DPDP Rules, 2025 expressly preserve sectoral localisation obligations, including RBI’s payment data direction, rather than displacing them. Companies regulated by both the DPDP Act and a sectoral regulator must satisfy both sets of requirements independently.

      Q: Could the DPDP Act’s cross-border and SDF timeline move earlier than May 2027?
      A: Possibly. MeitY proposed at a January 2026 stakeholder consultation to cut the Significant Data Fiduciary compliance window from eighteen months to twelve and to bring the cross-border transfer restriction into force immediately, rather than waiting for the full May 13, 2027 commencement. As of this writing, that remains a consultation proposal rather than a gazetted amendment, but companies should not assume May 2027 is a fixed date and should track MeitY’s notifications directly.

      Regulatory references
      • Payment and Settlement Systems Act, 2007, Section 17 (RBI enforcement powers)
      • RBI circular DPSS.CO.OD No.2785/06.08.005/2017-18 dated April 6, 2018, “Storage of Payment System Data”
      • RBI FAQs on Storage of Payment System Data, dated June 26, 2019
      • Reserve Bank of India (Digital Lending) Directions, 2025 (RBI/2025-26/36, DOR.STR.REC.19/21.07.001/2025-26 dated May 8, 2025), which repealed the September 2, 2022 Guidelines on Digital Lending
      • Digital Personal Data Protection Act, 2023, Sections 8 to 10, 16, and 33
      • Digital Personal Data Protection Rules, 2025, notified by MeitY on November 13, 2025, in particular Rule 15 (transfer of personal data outside India)
      • SEBI circular SEBI/HO/ITD/ITD_VAPT/P/CIR/2023/033 dated March 6, 2023, “Framework for Adoption of Cloud Services by SEBI Regulated Entities (REs)”, Principle 3
      • UIDAI Circular No. 14 of 2025 dated November 4, 2025, on hosting of Hardware Security Modules and the Aadhaar Data Vault
      • IRDAI (Maintenance of Insurance Records) Regulations, 2015, Regulation 3(9)
      • Companies Act, 2013, Section 128 (maintenance of books of account)
      • CERT-In Cybersecurity Directions, 2022, issued under Section 70B of the Information Technology Act, 2000
      About the Author
      Treelife
      Treelife social-linkedin
      Treelife Team | support@treelife.in

      We are a legal and finance firm with a deep focus on the startup ecosystem. We offer a wide range of services, including Virtual CFO, Legal Support, Tax & Regulatory, and Global Expansion assistance.

      Our goal at Treelife is to provide you with peace of mind and ease in business.

      Reviewed By
      Garima Mitra
      Garima Mitra linkedin
      Co-founder

      Spearheads Transactions, Contracts, and Compliance verticals at Treelife, combining expertise in business law with a focus on startup legal and governance.

      Sanmita Poojari
      Sanmita Poojari linkedin
      Senior Associate | Compliance

      Corporate compliance specialist with deep expertise in secretarial practices, regulatory filings, corporate governance, and advisory for startups.

      We Are Problem Solvers. And Take Accountability.

      Related Posts

      Set up EV Manufacturing in India: Entities, Licenses, Incentives
      Set up EV Manufacturing in India: Entities, Licenses, Incentives

      Setting up EV manufacturing in India in 2026 means running two parallel tracks at once: a standard industrial setup track...

      Learn MoreLearn More
      Bonus Issue of Shares under Section 63: Conditions, Reserves
      Bonus Issue of Shares under Section 63: Conditions, Reserves

      A bonus issue converts a company's accumulated reserves into paid-up share capital and hands the additional shares to existing shareholders...

      Learn MoreLearn More
      Appointment and Resignation of a Director: DIR-12, DIR-11, Consent
      Appointment and Resignation of a Director: DIR-12, DIR-11, Consent

      Every change to a company's board, whether a new appointment, a resignation, or a designation change, has to be reported...

      Learn MoreLearn More

      For Customer Support

      Mumbai | Delhi |
      Bangalore

      Speak to Us!

      We respond within 60 minutes.

        Your information is confidential and secure


        Let's talk.

        We've seen most founder problems before. Tell us yours.

        Error: Contact form not found.

        Typically responds within 4 hours
        Or reach out directly